Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pg3-5vwj-wh4m

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

EPSS

Процентиль: 89%
0.04763
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

EPSS

Процентиль: 89%
0.04763
Низкий

Дефекты

CWE-434